PT-2025-21175 · Bullfrog · Bullfrog

Vin01

·

Published

2025-05-14

·

Updated

2025-07-11

·

CVE-2025-47775

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Bullfrog versions prior to 0.8.4
Description: Bullfrog is a GitHub Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration, which can result in sandbox bypass.
Recommendations: For versions prior to 0.8.4, update to version 0.8.4 to fix the issue. As a temporary workaround, consider avoiding the use of tcp in GitHub workflows until the update is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-15958
CVE-2025-47775
GHSA-M32F-FJW2-37V3

Affected Products

Bullfrog